W32/Jeefo-A

Categoría: Virus y programas espía Protección disponible desde:31 jul 2003 00:00:00 (GMT)
Tipo: Win32 executable file virus Última actualización:13 ene 2011 15:40:20 (GMT)
Predominio:

Download Descargue nuestra herramienta gratuita para la eliminación de virus - Encuentre las amenazas no detectadas por su antivirus

W32/Jeefo-A infects Windows PE executables with an extension of EXE and a size
greater than 102,399 bytes, in all folders of all fixed drives C: - Z:.

The virus runs continuously in the background, infecting files periodically.

Under Win9x the virus creates the following registry entry
so that the virus is run automatically each time Windows is started:

HKLM\Software\Microsoft\Windows\CurrentVersion\
RunServices\PowerManager = <pathname this>

Under NT-based Windows platforms (inc. Windows 2000 and XP) the virus creates
a service named PowerManager with the startup type set to Automatic, so that
the virus service is launched automatically on startup.

When an infected file is run, the virus dropper is extracted to the Windows
folder as SVCHOST.EXE and the virus then disinfects the host executable,
although not all infected files will be successfully repaired.

descargar Pruebe los productos de Sophos totalmente gratis
Descargue una evaluación gratuita